CVE Feed

    Dashboard / CVE

    7.5
    High

    CVE-2019-20820

    Last Modified: 21 Nov 2024

    An issue was discovered in Foxit Reader and PhantomPDF before 9.7. It has a NULL pointer dereference during the parsing of file data.

    Published: 4 Jun 2020
    7.5
    High

    CVE-2019-20819

    Last Modified: 21 Nov 2024

    An issue was discovered in Foxit Reader and PhantomPDF before 9.7. It allows stack consumption via nested function calls for XML parsing.

    Published: 4 Jun 2020
    7.5
    High

    CVE-2019-20818

    Last Modified: 21 Nov 2024

    An issue was discovered in Foxit Reader and PhantomPDF before 9.7. It allows memory consumption because data is created for each page of an application level.

    Published: 4 Jun 2020
    7.5
    High

    CVE-2019-20817

    Last Modified: 21 Nov 2024

    An issue was discovered in Foxit Reader and PhantomPDF before 9.7. It has a NULL pointer dereference.

    Published: 4 Jun 2020
    7.5
    High

    CVE-2019-20816

    Last Modified: 21 Nov 2024

    An issue was discovered in Foxit PhantomPDF before 8.3.12. It has a NULL pointer dereference during the parsing of file data.

    Published: 4 Jun 2020
    7.5
    High

    CVE-2019-20815

    Last Modified: 21 Nov 2024

    An issue was discovered in Foxit PhantomPDF before 8.3.12. It allows stack consumption via nested function calls for XML parsing.

    Published: 4 Jun 2020
    7.5
    High

    CVE-2019-20814

    Last Modified: 21 Nov 2024

    An issue was discovered in Foxit PhantomPDF before 8.3.12. It allows memory consumption because data is created for each page of an application level.

    Published: 4 Jun 2020
    7.5
    High

    CVE-2019-20813

    Last Modified: 21 Nov 2024

    An issue was discovered in Foxit PhantomPDF before 8.3.12. It has a NULL pointer dereference.

    Published: 4 Jun 2020
    7.5
    High

    CVE-2020-13815

    Last Modified: 21 Nov 2024

    An issue was discovered in Foxit Reader and PhantomPDF before 9.7.1. It allows stack consumption via a loop of an indirect object reference.

    Published: 4 Jun 2020
    9.8
    Critical

    CVE-2020-13814

    Last Modified: 21 Nov 2024

    An issue was discovered in Foxit Reader and PhantomPDF before 9.7.1. It has a use-after-free via a document that lacks a dictionary.

    Published: 4 Jun 2020
    7.8
    High

    CVE-2020-13813

    Last Modified: 21 Nov 2024

    An issue was discovered in Foxit Studio Photo before 3.6.6.922. It allows local users to gain privileges via a crafted DLL in the current working directory when FoxitStudioPhoto366_3.6.6.916.exe is used.

    Published: 4 Jun 2020
    6.5
    Medium

    CVE-2019-16384

    Last Modified: 21 Nov 2024

    Cybele Thinfinity VirtualUI 2.5.17.2 allows ../ path traversal that can be used for data exfiltration. This enables files outside of the web directory to be retrieved if the exact location is known and the user has permissions.

    Published: 4 Jun 2020
    6.1
    Medium

    CVE-2019-16385

    Last Modified: 21 Nov 2024

    Cybele Thinfinity VirtualUI 2.5.17.2 allows HTTP response splitting via the mimetype parameter within a PDF viewer request, as demonstrated by an example.pdf?mimetype= substring. The victim user must load an application request to view a PDF, containing the malicious payload. This results in a reflected XSS payload being executed.

    Published: 4 Jun 2020
    7.8
    High

    CVE-2020-13812

    Last Modified: 21 Nov 2024

    An issue was discovered in Foxit Studio Photo before 3.6.6.922. It allows local users to gain privileges via a crafted DLL in the current working directory.

    Published: 4 Jun 2020
    7.8
    High

    CVE-2020-13811

    Last Modified: 21 Nov 2024

    An issue was discovered in Foxit Studio Photo before 3.6.6.922. It has an out-of-bounds write via a crafted TIFF file.

    Published: 4 Jun 2020
    7.5
    High

    CVE-2020-13810

    Last Modified: 21 Nov 2024

    An issue was discovered in Foxit Reader and PhantomPDF before 9.7.2. It allows signature validation bypass via a modified file or a file with non-standard signatures.

    Published: 4 Jun 2020
    7.5
    High

    CVE-2020-13808

    Last Modified: 21 Nov 2024

    An issue was discovered in Foxit Reader and PhantomPDF before 9.7.2. It allows resource consumption via crafted cross-reference stream data.

    Published: 4 Jun 2020
    7.5
    High

    CVE-2020-13809

    Last Modified: 21 Nov 2024

    An issue was discovered in Foxit Reader and PhantomPDF before 9.7.2. It allows resource consumption via long strings in the content stream.

    Published: 4 Jun 2020
    7.5
    High

    CVE-2020-13807

    Last Modified: 21 Nov 2024

    An issue was discovered in Foxit Reader and PhantomPDF before 9.7.2. It has circular reference mishandling that causes a loop.

    Published: 4 Jun 2020
    6.1
    Medium

    CVE-2020-13827

    Last Modified: 21 Nov 2024

    phpList before 3.5.4 allows XSS via /lists/admin/user.php and /lists/admin/users.php.

    Published: 4 Jun 2020
    7.5
    High

    CVE-2020-13806

    Last Modified: 21 Nov 2024

    An issue was discovered in Foxit Reader and PhantomPDF before 9.7.2. It has a use-after-free because of JavaScript execution after a deletion or close operation.

    Published: 4 Jun 2020
    9.8
    Critical

    CVE-2020-13805

    Last Modified: 21 Nov 2024

    An issue was discovered in Foxit Reader and PhantomPDF before 9.7.2. It has brute-force attack mishandling because the CAS service lacks a limit on login failures.

    Published: 4 Jun 2020
    9.8
    Critical

    CVE-2020-13804

    Last Modified: 21 Nov 2024

    An issue was discovered in Foxit Reader and PhantomPDF before 9.7.2. It allows information disclosure of a hardcoded username and password in the DocuSign plugin.

    Published: 4 Jun 2020
    7.5
    High

    CVE-2020-13803

    Last Modified: 21 Nov 2024

    An issue was discovered in Foxit PhantomPDF Mac and Foxit Reader for Mac before 4.0. It allows signature validation bypass via a modified file or a file with non-standard signatures.

    Published: 4 Jun 2020
    7.6
    High

    CVE-2020-4509

    Last Modified: 21 Nov 2024

    IBM QRadar SIEM 7.3 and 7.4 is vulnerable to an XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive information or consume memory resources. IBM X-Force ID: 182364.

    Published: 4 Jun 2020
    9.8
    Critical

    CVE-2020-4193

    Last Modified: 21 Nov 2024

    IBM Security Guardium 11.1 uses an inadequate account lockout setting that could allow a remote attacker to brute force account credentials. IBM X-Force ID: 174857.

    Published: 4 Jun 2020
    4.4
    Medium

    CVE-2020-4191

    Last Modified: 21 Nov 2024

    IBM Security Guardium 11.1 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. IBM X-Force ID: 174852.

    Published: 4 Jun 2020
    6.1
    Medium

    CVE-2020-4183

    Last Modified: 21 Nov 2024

    IBM Security Guardium 11.1 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 174739.

    Published: 4 Jun 2020
    7.5
    High

    CVE-2020-13818

    Last Modified: 21 Nov 2024

    In Zoho ManageEngine OpManager before 125144, when <cachestart> is used, directory traversal validation can be bypassed.

    Published: 4 Jun 2020
    5.4
    Medium

    CVE-2020-6640

    Last Modified: 21 Nov 2024

    An improper neutralization of input vulnerability in the Admin Profile of FortiAnalyzer may allow a remote authenticated attacker to perform a stored cross site scripting attack (XSS) via the Description Area.

    Published: 4 Jun 2020
    9.8
    Critical

    CVE-2020-9292

    Last Modified: 21 Nov 2024

    An unquoted service path vulnerability in the FortiSIEM Windows Agent component may allow an attacker to gain elevated privileges via the AoWinAgt executable service path.

    Published: 4 Jun 2020
    5.5
    Medium

    CVE-2019-16150

    Last Modified: 21 Nov 2024

    Use of a hard-coded cryptographic key to encrypt security sensitive data in local storage and configuration in FortiClient for Windows prior to 6.4.0 may allow an attacker with access to the local storage or the configuration backup file to decrypt the sensitive data via knowledge of the hard-coded key.

    Published: 4 Jun 2020
    7.8
    High

    CVE-2020-10757

    Last Modified: 21 Nov 2024

    A flaw was found in the Linux Kernel in versions after 4.5-rc1 in the way mremap handled DAX Huge Pages. This flaw allows a local attacker with access to a DAX enabled storage to escalate their privileges on the system.

    Published: 4 Jun 2020
    9.8
    Critical

    CVE-2020-10546

    Last Modified: 21 Nov 2024

    rConfig 3.9.4 and previous versions has unauthenticated compliancepolicies.inc.php SQL injection. Because, by default, nodes' passwords are stored in cleartext, this vulnerability leads to lateral movement, granting an attacker access to monitored network devices.

    Published: 4 Jun 2020
    9.8
    Critical

    CVE-2020-10547

    Last Modified: 21 Nov 2024

    rConfig 3.9.4 and previous versions has unauthenticated compliancepolicyelements.inc.php SQL injection. Because, by default, nodes' passwords are stored in cleartext, this vulnerability leads to lateral movement, granting an attacker access to monitored network devices.

    Published: 4 Jun 2020
    9.8
    Critical

    CVE-2020-10548

    Last Modified: 21 Nov 2024

    rConfig 3.9.4 and previous versions has unauthenticated devices.inc.php SQL injection. Because, by default, nodes' passwords are stored in cleartext, this vulnerability leads to lateral movement, granting an attacker access to monitored network devices.

    Published: 4 Jun 2020
    9.8
    Critical

    CVE-2020-10549

    Last Modified: 21 Nov 2024

    rConfig 3.9.4 and previous versions has unauthenticated snippets.inc.php SQL injection. Because, by default, nodes' passwords are stored in cleartext, this vulnerability leads to lateral movement, granting an attacker access to monitored network devices.

    Published: 4 Jun 2020
    5.5
    Medium

    CVE-2020-12049

    Last Modified: 21 Nov 2024

    An issue was discovered in dbus >= 1.3.0 before 1.12.18. The DBusServer in libdbus, as used in dbus-daemon, leaks file descriptors when a message exceeds the per-message file descriptor limit. A local attacker with access to the D-Bus system bus or another system service's private AF_UNIX socket could use this to make the system service reach its file descriptor limit, denying service to subsequent D-Bus clients.

    Published: 4 Jun 2020
    7.7
    High

    CVE-2020-13692

    Last Modified: 21 Nov 2024

    PostgreSQL JDBC Driver (aka PgJDBC) before 42.2.13 allows XXE.

    Published: 4 Jun 2020
    7.1
    High

    CVE-2020-10771

    Last Modified: 21 Nov 2024

    A flaw was found in Infinispan version 10, where it is possible to perform various actions that could have side effects using GET requests. This flaw allows an attacker to perform a cross-site request forgery (CSRF) attack.

    Published: 4 Jun 2020
    5.5
    Medium

    CVE-2020-7030

    Last Modified: 21 Nov 2024

    A sensitive information disclosure vulnerability was discovered in the web interface component of IP Office that may potentially allow a local user to gain unauthorized access to the component. Affected versions of IP Office include: 9.x, 10.0 through 10.1.0.7 and 11.0 though 11.0.4.3.

    Published: 3 Jun 2020
    6.1
    Medium

    CVE-2020-11094

    Last Modified: 21 Nov 2024

    The October CMS debugbar plugin before version 3.1.0 contains a feature where it will log all requests (and all information pertaining to each request including session data) whenever it is enabled. This presents a problem if the plugin is ever enabled on a system that is open to untrusted users as the potential exists for them to use this feature to view all requests being made to the application and obtain sensitive information from those requests. There even exists the potential for account takeovers of authenticated users by non-authenticated public users, which would then lead to a number of other potential issues as an attacker could theoretically get full access to the system if the required conditions existed. Issue has been patched in v3.1.0 by locking down access to the debugbar to all users; it now requires an authenticated backend user with a specifically enabled permission before it is even usable, and the feature that allows access to stored request information is restricted behind a different permission that's more restrictive.

    Published: 3 Jun 2020
    5.8
    Medium

    CVE-2020-11091

    Last Modified: 21 Nov 2024

    In Weave Net before version 2.6.3, an attacker able to run a process as root in a container is able to respond to DNS requests from the host and thereby insert themselves as a fake service. In a cluster with an IPv4 internal network, if IPv6 is not totally disabled on the host (via ipv6.disable=1 on the kernel cmdline), it will be either unconfigured or configured on some interfaces, but it's pretty likely that ipv6 forwarding is disabled, ie /proc/sys/net/ipv6/conf//forwarding == 0. Also by default, /proc/sys/net/ipv6/conf//accept_ra == 1. The combination of these 2 sysctls means that the host accepts router advertisements and configure the IPv6 stack using them. By sending rogue router advertisements, an attacker can reconfigure the host to redirect part or all of the IPv6 traffic of the host to the attacker controlled container. Even if there was no IPv6 traffic before, if the DNS returns A (IPv4) and AAAA (IPv6) records, many HTTP libraries will try to connect via IPv6 first then fallback to IPv4, giving an opportunity to the attacker to respond. If by chance you also have on the host a vulnerability like last year's RCE in apt (CVE-2019-3462), you can now escalate to the host. Weave Net version 2.6.3 disables the accept_ra option on the veth devices that it creates.

    Published: 3 Jun 2020
    8.8
    High

    CVE-2011-1805

    Last Modified: 21 Nov 2024

    Bad cast in CSS in Google Chrome prior to 11.0.0.0 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

    Published: 3 Jun 2020
    6.5
    Medium

    CVE-2011-2863

    Last Modified: 21 Nov 2024

    Insufficient policy enforcement in V8 in Google Chrome prior to 14.0.0.0 allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted HTML page.

    Published: 3 Jun 2020
    4
    Medium

    CVE-2020-5299

    Last Modified: 21 Nov 2024

    In OctoberCMS (october/october composer package) versions from 1.0.319 and before 1.0.466, any users with the ability to modify any data that could eventually be exported as a CSV file from the `ImportExportController` could potentially introduce a CSV injection into the data to cause the generated CSV export file to be malicious. This requires attackers to achieve the following before a successful attack can be completed: 1. Have found a vulnerability in the victims spreadsheet software of choice. 2. Control data that would potentially be exported through the `ImportExportController` by a theoretical victim. 3. Convince the victim to export above data as a CSV and run it in vulnerable spreadsheet software while also bypassing any sanity checks by said software. Issue has been patched in Build 466 (v1.0.466).

    Published: 3 Jun 2020
    6.2
    Medium

    CVE-2020-5296

    Last Modified: 21 Nov 2024

    In OctoberCMS (october/october composer package) versions from 1.0.319 and before 1.0.466, an attacker can exploit this vulnerability to delete arbitrary local files of an October CMS server. The vulnerability is only exploitable by an authenticated backend user with the `cms.manage_assets` permission. Issue has been patched in Build 466 (v1.0.466).

    Published: 3 Jun 2020
    3.4
    Low

    CVE-2020-5297

    Last Modified: 21 Nov 2024

    In OctoberCMS (october/october composer package) versions from 1.0.319 and before 1.0.466, an attacker can exploit this vulnerability to upload jpg, jpeg, bmp, png, webp, gif, ico, css, js, woff, woff2, svg, ttf, eot, json, md, less, sass, scss, xml files to any directory of an October CMS server. The vulnerability is only exploitable by an authenticated backend user with the `cms.manage_assets` permission. Issue has been patched in Build 466 (v1.0.466).

    Published: 3 Jun 2020
    4
    Medium

    CVE-2020-5298

    Last Modified: 21 Nov 2024

    In OctoberCMS (october/october composer package) versions from 1.0.319 and before 1.0.466, a user with the ability to use the import functionality of the `ImportExportController` behavior can be socially engineered by an attacker to upload a maliciously crafted CSV file which could result in a reflected XSS attack on the user in question Issue has been patched in Build 466 (v1.0.466).

    Published: 3 Jun 2020
    4.8
    Medium

    CVE-2020-5295

    Last Modified: 21 Nov 2024

    In OctoberCMS (october/october composer package) versions from 1.0.319 and before 1.0.466, an attacker can exploit this vulnerability to read local files of an October CMS server. The vulnerability is only exploitable by an authenticated backend user with the `cms.manage_assets` permission. Issue has been patched in Build 466 (v1.0.466).

    Published: 3 Jun 2020